# 09 — Pre-deploy checklist (recurring) Run this before every production deploy (first deploy and each tagged release). Dev-login is intentionally retained behind a double gate; this checklist is what keeps that gate honest. ## README - [ ] `README.md` reflects the current module list and any env vars added since the last release. ## Env hygiene - [ ] Server `.env` (next to `deploy/compose.yaml`) does **not** set: - `ENABLE_DEV_LOGIN` - `DEV_LOGIN_EMAIL`, `DEV_LOGIN_NAME`, `DEV_HOUSEHOLD_NAME` - [ ] Server `.env` sets real values for: - `NEXT_PUBLIC_APP_URL` (https) - `AUTH_SECRET` (`openssl rand -base64 32`) - `AUTH_OIDC_ISSUER`, `AUTH_OIDC_CLIENT_ID`, `AUTH_OIDC_CLIENT_SECRET` - `VAPID_PUBLIC_KEY`, `VAPID_PRIVATE_KEY`, `VAPID_SUBJECT` - `FAMAPP_DB_*`, `AUTHENTIK_DB_*`, `AUTHENTIK_SECRET_KEY` - [ ] `FAMAPP_IMAGE` pins a specific version tag (`ghcr.io/ginnoir/famapp:vX.Y.Z`), not `latest`, after first deploy. ## Code-side guard `src/lib/dev-login-config.ts` throws on import if `NODE_ENV=production` and `ENABLE_DEV_LOGIN=true`. Container will refuse to start. - [ ] Confirm guard is still present (do not remove without updating this checklist). ## Smoke after deploy - [ ] `https://fam.ginnoir.com/login` shows only **Sign in with SSO** (no Dev login button). - [ ] Real Authentik sign-in succeeds, lands on dashboard. - [ ] First user appears in DB with household membership, default calendars, default lists. - [ ] No `dev@famapp.local` row in production `users` table. - [ ] Push opt-in works (settings → enable → test notification arrives). - [ ] A share link created from `/settings` resolves at `/s/` while signed out. ## Backup / rollback - [ ] Last `famapp-backup` cron run succeeded (check container logs). - [ ] Previous image tag is known and recorded in `CHANGELOG.md`, so rollback = bump `FAMAPP_IMAGE` and `docker compose up -d famapp`.